The PRA's Supervisory Statement SS1/23 — the most significant model risk management framework issued by a UK regulator since the financial crisis — came into legal force on 17 May 2024. Its five principles apply to all material models used by regulated UK banks, building societies, and PRA-designated investment firms. They explicitly include End User Computing tools: spreadsheets, SAS programmes, and offline calculations that sit outside formal model inventory systems.
Most compliance programmes focused on the visible model estate — the IFRS 9 models, the IRB capital models, the stress testing frameworks. These were already inventoried, already partially governed. The EUC estate beneath them was a different matter: largely undocumented, informally maintained, and absent from most model risk governance frameworks entirely.
More than a year after the legal deadline, that gap remains the most common SS1/23 compliance deficiency identified in supervisory engagement. It is also the most addressable — if the organisation knows where to start.
What SS1/23 actually requires
SS1/23 sets out five principles for model risk management. They are overarching in scope — the PRA was deliberate about this. The statement applies to all types of models used to inform business decisions, whether developed in-house or externally, regardless of technology, and including models used for financial reporting purposes.
The explicit inclusion of EUC tools was not accidental. The PRA observed, during its supervisory work in the years preceding SS1/23, that some of the most material model risk in regulated firms was sitting in assets that had never been formally identified as models at all — spreadsheets built by business analysts, SAS programmes maintained by a single person, Access databases feeding regulatory returns with no documentation and no governance trail.
Model Identification & Classification
Firms must identify all models in use — including EUC tools — and classify them by materiality and risk. Most EUC assets have never been inventoried at all.
⚠ Common EUC gap: absent from model inventory
Governance & Policies
Clear ownership, documented methodology, and Board-level oversight of model risk. EUC assets typically have informal ownership at best — often reverting to whoever maintains the file.
⚠ Common EUC gap: no formal owner, no documented methodology
Model Development & Implementation
Models must be developed with documented rationale, tested, and formally approved before use. Most EUC tools were built to solve an immediate problem — documentation came later, if at all.
⚠ Common EUC gap: no development documentation or approval record
Model Validation
Independent validation of model methodology, assumptions, and outputs. The PRA expects this to be performed by a function independent of model development. For EUC tools, independent validation has almost never been performed.
⚠ Common EUC gap: never independently validated
Model Risk Mitigants
Where a model is known to underperform or carries identified deficiencies, firms must have clear policies for restricting its use, applying post-model adjustments, and escalating concerns to the appropriate people. For most EUCs, no such process exists — known issues get quietly worked around rather than formally flagged, restricted, or escalated.
⚠ Common EUC gap: no formal process for restricting, adjusting, or escalating known issues
"The PRA did not write EUC tools into SS1/23 as an afterthought. It wrote them in because supervisory experience showed they were where the real risk was hiding."
The compliance programme that stopped too soon
When SS1/23 was published in May 2023 and firms had twelve months to prepare, most compliance programmes followed a logical prioritisation: address the formal model inventory first, then work outward. The IRB capital models, the IFRS 9 impairment models, the stress testing frameworks — these were the assets already known, already partially governed, and carrying the highest regulatory visibility.
The EUC estate was different. It was not on the model inventory because it had never been inventoried. It was not in the governance framework because nobody had formally decided it needed to be. And by the time the May 2024 deadline arrived, many firms had completed their visible compliance programme while the EUC layer beneath it remained untouched.
Deloitte's pre-implementation analysis noted that the PRA will expect firms within scope to demonstrate a high level of compliance from day one — and that the probability of the PRA commissioning a skilled person report (s.166 review) for banks falling short of SS1/23 expectations is high.
A s.166 review is not a voluntary exercise. It is conducted by an external reviewer appointed by and reporting to the PRA, at the firm's expense. The findings go directly to the regulator. For firms with material EUC assets feeding regulatory outputs that have never been through a governance framework, this is a live and foreseeable risk — not a theoretical one.
What closing the gap requires
Closing the SS1/23 EUC gap is not a single action. It is a structured programme of work that begins with knowing what you have and ends with being able to demonstrate, to a regulator, that every material EUC asset has been identified, documented, owned, and assessed.
The starting point is always the same: a systematic inventory and deconstruction of the EUC estate. Not a spreadsheet list of file names — a documented understanding of what each asset does, what data it uses, what logic it applies, what outputs it produces, and what governance it currently has or lacks.
SS1/23 Principle 2 requires that model methodology is documented to a standard that enables an independent reviewer to understand and reproduce the model without requiring assistance from the model developer. For most EUC assets, this standard has never been met — the documentation, where it exists at all, is limited to cell comments and an incomplete change log.
Principle 4 requires that validation is performed by a function independent of model development. For EUC tools built and maintained by business teams, this means the validation cannot be performed by the same team — or even the same business unit. External review by a specialist with model risk governance experience is what the PRA expects.
Structured deconstruction that closes the SS1/23 EUC gap.
A Greywood Analytics engagement is specifically designed to produce the documentation that SS1/23 requires — and to position each asset for the governance steps that follow. For every EUC asset in scope, we deliver:
- Plain English Summary — what the asset does, what it produces, who owns it, and what the key governance gaps are. Directly addresses SS1/23 Principles 1 and 2.
- Dependency Map — every data flow, formula chain, and cross-system dependency mapped and rated for fragility. Essential for SS1/23 Principle 3 documentation requirements.
- Risk & Assumption Narrative — every identified risk and governance gap cited against SS1/23 by principle number. Structured for immediate use by model risk and compliance teams.
- Risk Register — complete register with prioritised remediation plan, giving model risk teams a clear path from current state to SS1/23 compliance. Addresses Principles 1, 2, 4, and 5.
- Rating Calibration Statement — for assets feeding regulatory returns, a methodology defence document explaining every risk score to any reviewer — including a PRA skilled person.
Our deconstruction constitutes the independent review that SS1/23 Principle 4 requires — conducted by a specialist with Financial Services model risk experience, outside the business unit, with full documented evidence of findings.
First deliverable pack typically received within 2–3 working days of engagement start.
The gap is still closeable
The May 2024 deadline has passed. But SS1/23 compliance is not a binary state — it is an ongoing supervisory expectation. Firms that can demonstrate a credible, evidence-based programme of EUC governance remediation are in a materially better position than firms that cannot, regardless of where that programme started.
The PRA's supervisory engagement is ongoing. The s.166 risk is real. And the EUC assets that have never been through a governance framework — the ones built by analysts who have since left, running on scheduled jobs nobody fully understands, feeding outputs that go to the Board and the regulator — are still there.
The gap is still closeable. The question is whether your organisation closes it proactively, or waits for a supervisory conversation that forces the issue on someone else's timeline.
"SS1/23 did not create the EUC risk. It created the obligation to address it — and a deadline that has already passed."Greywood Analytics
If your organisation has material EUC assets that have not yet been assessed against SS1/23, we can help you understand the gap and close it — starting with a no-commitment scoping conversation.
Start a Conversation